Skip to content

Docker daemon crash during image pull of malicious image

Moderate
tiborvass published GHSA-6fj5-m822-rqx8 Feb 2, 2021

Package

docker-ce

Affected versions

< 19.03.15, < 20.10.3

Patched versions

19.03.15, 20.10.3

Description

Impact

Pulling an intentionally malformed Docker image manifest crashes the dockerd daemon.

Patches

Versions 20.10.3 and 19.03.15 contain patches that prevent the daemon from crashing.

Credits

Maintainers would like to thank Josh Larsen, Ian Coldwater, Duffie Cooley, Rory McCune for working on the vulnerability and Brad Geesaman for responsibly disclosing it to security@docker.com.

Severity

Moderate

CVE ID

CVE-2021-21285

Weaknesses

No CWEs

Credits